Complete Nmap keyboard shortcuts and commands reference — 15 shortcuts across 2 categories. Quick reference cheat sheet for Windows & Mac.
Nmap's option set is large, and this page lists the invocations that answer the usual questions — what is up, what is listening, what version is it — plus the flags that make output usable. Every command needs a target and most need root for raw sockets. The notes explain what each scan actually sends, because that decides how long it takes and what a firewall sees.
| Shortcut | Action |
|---|---|
| nmap <target> | Basic scan |
| nmap -sV <target> | Service version |
| nmap -O <target> | OS detection |
| nmap -A <target> | Aggressive scan |
| nmap -p 80,443 <target> | Specific ports |
| nmap -p- <target> | All ports |
| nmap -sU <target> | UDP scan |
| Shortcut | Action |
|---|---|
| nmap -sn 192.168.1.0/24 | Ping sweep |
| nmap --script vuln <target> | Vuln scan |
| nmap -T4 <target> | Fast timing |
| nmap -oN output.txt | Save output |
| nmap -oX output.xml | XML output |
| nmap -v <target> | Verbose |
| nmap -iL hosts.txt | Input from file |
| nmap --open <target> | Open ports only |
The most essential Nmap shortcuts are: nmap <target> (Basic scan), nmap -sV <target> (Service version), nmap -O <target> (OS detection).
The Nmap shortcut for basic scan is nmap <target>.
Yes — use My Stack to combine Nmap shortcuts with any other platform on this site into one printable reference, which is useful if your daily workflow spans several tools.
nmap -sn 192.168.1.0/24 is a ping sweep: hosts that answer, no port scan, and the way to map a subnet in seconds. nmap <target> then scans the thousand most common TCP ports; nmap -p 80,443 <target> limits to named ports and nmap -p- <target> scans all 65,535, which takes minutes rather than seconds. nmap -sV <target> probes open ports to identify the service and version, nmap -O <target> guesses the operating system from TCP/IP fingerprints, and nmap -A <target> turns on both plus scripts and traceroute — the noisy, thorough option. nmap -sU <target> scans UDP, which is slow because closed ports usually stay silent.
nmap -T4 <target> speeds up timing for a reliable LAN (T5 is faster still and drops results on flaky links). nmap --open <target> shows only open ports, and nmap -iL hosts.txt reads targets from a file. nmap --script vuln <target> runs the vulnerability-detection scripts from the NSE library against the discovered services — useful for a first pass, but the scripts vary in accuracy and the category name should not be mistaken for a full assessment.
nmap -oN output.txt writes the normal text output, nmap -oX output.xml writes XML that other tools import, and -oA basename writes normal, XML and grepable at once — the habit worth forming before a long scan. nmap -v <target> prints progress and open ports as they are found rather than at the end. Scanning networks you do not own or have permission to test is illegal in most jurisdictions; keep scope to systems you are authorised to examine.
Open your assistant with this page preloaded as the source — great for follow-up questions like "which of these work in other apps?"